Skip to content

Commit 0e42395

Browse files
chore: Add SECURITY policy that conforms with OSSF requirements (#825)
--------- Co-authored-by: George L. Yermulnik <[email protected]>
1 parent 1d67ef3 commit 0e42395

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed

.github/SECURITY.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
# Reporting a Vulnerability
2+
3+
If you believe you have discovered a potential security vulnerability in this project, please report it securely. **Do not create a public GitHub issue for any security concerns.**
4+
5+
## How to Report
6+
7+
Send an email with a detailed description of the vulnerability, including any evidence of the disclosure, the impact, and any timelines related to the issue to: [[email protected]](mailto:[email protected])
8+
9+
## Vulnerability Disclosure Process
10+
11+
- **Confidential Disclosure:** All vulnerability reports will be kept confidential until a fix is developed and verified.
12+
- **Assessment and Response:** We aim to acknowledge any valid report within 15 business days.
13+
- **Timelines:** After verification, we plan to have a coordinated disclosure within 60 days, though this may vary depending on the complexity of the fix.
14+
- **Communication:** We will work directly with the vulnerability reporter to clarify details, answer questions, and discuss potential mitigations.
15+
- **Updates:** We may provide periodic updates on the progress of the remediation of the reported vulnerability.
16+
17+
## Guidelines
18+
19+
- **Vulnerability Definition:** A vulnerability is any flaw or weakness in this project that can be exploited to compromise system security.
20+
- **Disclosure Expectations:** When you report a vulnerability, please include as much detail as possible to allow us to assess its validity and scope without exposing sensitive information publicly.
21+
22+
By following this process, you help us improve the security of our project while protecting users and maintainers. We appreciate your efforts to responsibly disclose vulnerabilities.

0 commit comments

Comments
 (0)